← Blog · · df00tech

Payload CMS: Access Control Bypass Allows Unauthorized Collection Document Updates (CVE-2026-105859)

breaking ghsa npm CVE-2026-105859

What happened

Payload CMS published GHSA-f7hx-52q9-hcrf disclosing an access control bypass tracked as CVE-2026-105859, rated CVSS 9.8 with a public proof-of-concept reportedly available. According to the advisory, a specific endpoint allows an attacker to submit a request that updates collection documents regardless of configured access control and field-level access control. The affected configuration is any collection or join field with orderable: true enabled. Payload has patched the issue; the advisory recommends upgrading to >= 3.90.0 or >= 4.0.0-canary.34.

Why it matters

Payload is a widely used headless CMS, and access control bypasses on document-update endpoints are high-impact by nature: they can let unauthenticated or under-privileged callers modify content, metadata, or fields that were explicitly gated. The combination of a 9.8 CVSS score, a public PoC, and a relatively narrow trigger condition (use of orderable: true) means exploitation is plausible wherever that setting is in use, even though the overall blast radius depends on how many sites enable orderable collections/join fields.

Who's affected

  • Any deployment running Payload CMS versions prior to the patched releases
  • Specifically, any project configuring orderable: true on a collection or join field

What defenders should do now

  • Inventory Payload CMS deployments and check package.json/lockfiles for the payload npm package version
  • Search codebase/config for orderable: true usage on collections or join fields to confirm exposure
  • Upgrade to Payload >= 3.90.0 (or >= 4.0.0-canary.34 on the canary track) as soon as possible given the public PoC
  • Until patched, consider temporarily disabling or restricting access to affected collections, and review recent write/update activity on orderable collections for signs of unauthorized changes to documents that should have been access-controlled
  • Treat any logging or audit trail around the relevant update endpoint as a priority source for retroactive hunting once patched, since the bypass may not leave obvious signatures

Developing intel

This is a same-day advisory and details may evolve as the community analyzes the public PoC and real-world exploitation (if any) emerges. No ransomware campaign use has been reported at this time. For the authoritative technical details and patch guidance, see the original GitHub Security Advisory: GHSA-f7hx-52q9-hcrf.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.